Connected equipment, operational technology, remote access and increasingly digital supply chains are creating new dependencies for manufacturers. We look at five cyber risks West Midlands manufacturing businesses should understand and what they can do about them.
Contents
- Contents
- Five Cyber Risks Facing West Midlands Manufacturers
- Key Takeaways
- Risk One: IT and Operational Technology Are Becoming More Connected
- Risk Two: Remote Access Can Create Concentrated Exposure
- Risk Three: Industrial Technology Cannot Always Be Managed Like Office IT
- Risk Four: Supply-Chain Cyber Risk Extends Beyond Direct Technology Providers
- Risk Five: An Incident Plan That Ignores Production Is Incomplete
- Asset Visibility Connects All Five Risks
- Cyber Essentials Can Strengthen the Corporate Baseline
- Start with Operational Consequence Rather Than Cyber Complexity
- Industrial Cyber Resilience Is a Business-Continuity Discipline
Five Cyber Risks Facing West Midlands Manufacturers
Manufacturing businesses have always managed operational risk: equipment failure, interrupted supplies, quality problems, safety incidents and unexpected production stoppages. As factories, engineering environments and supply chains have become more digitally connected, cyber security has become another component of that operational risk rather than a separate problem belonging solely to the IT department.
Connected machinery, operational technology (OT), industrial software, remote maintenance, cloud platforms and digitally integrated suppliers can improve productivity and visibility across manufacturing operations. They also create dependencies that need to be understood. A cyber incident affecting an office system may interrupt administration; an incident reaching production technology can affect output, delivery commitments, equipment availability or, in some environments, safety.
The underlying regional analysis, The Missing Layer in the West Midlands Tech Narrative: Cyber as Industrial Resilience Infrastructure, argued that this relationship between digital dependency and industrial resilience deserves greater attention in a manufacturing-intensive economy such as the West Midlands. For individual manufacturers, the practical implication is that cyber security should increasingly be managed in relation to production, suppliers and business continuity, not simply corporate IT.
Five areas deserve particular attention: the relationship between IT and operational technology, remote access, legacy industrial systems, supply-chain dependency and the ability to continue operating when disruption occurs.
Read the wider regional analysis. The West Midlands Cyber Cluster examines why cyber resilience should increasingly be treated as part of the West Midlands’ industrial infrastructure rather than simply as an IT security issue, in the companion article “Cyber Resilience Is Industrial Infrastructure for the West Midlands”.
Key Takeaways
- Manufacturers need to understand where corporate IT and operational technology connect because an incident originating in ordinary business systems can create production consequences where those environments are insufficiently separated.
- Remote maintenance and supplier access can be operationally valuable but should be controlled according to the level of access being granted, particularly where external organisations can reach production systems.
- Industrial equipment often remains operational for considerably longer than conventional IT, making asset visibility, network design and compensating controls important where systems cannot simply be patched or replaced.
- Cyber risk extends through both technology suppliers and industrial supply chains, so manufacturers should identify which external organisations could materially affect operations if compromised or unavailable.
- Effective incident preparation should consider how production will continue, degrade safely or recover when important digital systems are unavailable, rather than concentrating only on restoring data.
Risk One: IT and Operational Technology Are Becoming More Connected
The distinction between information technology and operational technology remains useful because the two environments perform different functions.
IT generally includes the systems used to process information and run business activities: email, identity services, finance systems, laptops, cloud applications and corporate networks. OT encompasses technology that monitors or controls physical processes, including industrial control systems, programmable logic controllers, supervisory systems, manufacturing equipment and associated engineering technology.
Historically, many industrial environments were relatively isolated. That assumption is increasingly unreliable.
Manufacturers connect production systems to enterprise-resource-planning platforms, maintenance systems, data analytics, remote-support services and cloud infrastructure. Production data may be collected centrally for performance monitoring or predictive maintenance, while engineering teams and external vendors may require remote access to industrial equipment.
These connections can create substantial operational value. They can also create routes through which an incident affecting one environment influences another.
The practical requirement is not necessarily to disconnect OT from the rest of the organisation. Modern manufacturing frequently depends on connectivity. Businesses instead need to understand where connections exist, why they are required and what controls separate systems with different operational consequences.
Network segmentation can reduce unnecessary pathways between environments. Strong authentication and privileged-access controls can restrict who can reach sensitive systems. Monitoring can help identify unexpected communication, while asset inventories allow organisations to understand which devices and systems actually exist.
This last point is particularly important. Security decisions become difficult when the organisation lacks an accurate picture of its industrial environment.
For manufacturers beginning to examine OT security, mapping important systems, connections and dependencies is often more useful than immediately purchasing additional security technology.
Risk Two: Remote Access Can Create Concentrated Exposure
Industrial environments frequently depend on specialist suppliers.
Machine manufacturers, automation engineers, software providers and maintenance contractors may need access to equipment to diagnose faults, install updates or provide technical support. Remote connectivity can reduce downtime and avoid the delay and cost associated with sending engineers to site.
The security question is therefore not whether remote access should exist, but how it is controlled.
Persistent supplier accounts, shared credentials or broadly configured remote-access tools can create unnecessary exposure. An external organisation may also support several customers, meaning compromise of the supplier could potentially provide an attacker with access routes into multiple environments.
Manufacturers should understand who can access important systems remotely, how users authenticate, whether access is permanently available and what an external user can reach after connecting.
Where practical, privileged access should be limited to what is required for the task and removed when no longer needed. Multi-factor authentication can provide additional protection for remote accounts, while logging and monitoring make it easier to establish when access occurred and what activity took place.
The commercial relationship also deserves attention.
Security requirements should be considered when appointing suppliers rather than introduced only after access has been granted. Contracts can establish expectations around account management, incident notification and the handling of vulnerabilities, although contractual wording is valuable only where the organisation has a practical means of verifying or enforcing important requirements.
Smaller manufacturers may not have specialist teams to design complex privileged-access environments. Proportionality is important. Even relatively simple improvements, such as eliminating shared accounts, enabling multi-factor authentication and regularly reviewing active external access, can reduce avoidable exposure.
Risk Three: Industrial Technology Cannot Always Be Managed Like Office IT
Conventional IT security practice often assumes that vulnerable software can be patched, unsupported devices can be replaced and systems can be restarted when necessary.
Industrial environments complicate those assumptions.
Manufacturing equipment may remain in service for many years because replacement is expensive and the machinery continues to perform its production function effectively. Software can depend on specific operating-system versions or engineering applications, while changes may require testing to ensure they do not interfere with production.
An update that would be routine on an office laptop can therefore require considerably more planning in an industrial environment.
This does not mean that old technology should simply be accepted as an unavoidable security weakness. It means that risk sometimes needs to be managed through controls other than immediate replacement.
A manufacturer that knows an important system cannot be patched can restrict the network connections available to it, limit the users able to access it, monitor relevant traffic and ensure that unnecessary services are disabled. Where an obsolete system supports a critical process, the organisation can also plan for its eventual replacement rather than discovering the dependency during an incident or equipment failure.
Asset management becomes central to this process.
Manufacturers should know which systems are critical to production, which operating systems and software they depend on, who supports them and whether the underlying technology remains within vendor support.
The UK cyber provider market illustrates the specialist nature of this work. The 2026 Cyber Security Sectoral Analysis associates around 7% of providers with SCADA or industrial-control-system security, while analysis of company websites identifies industrial or OT security among approximately 10% of offerings.
Specialist expertise is therefore a smaller part of the cyber market than general consultancy or governance services. Manufacturers seeking external support should check that providers understand industrial operating constraints rather than assuming that conventional enterprise-security approaches can be transferred unchanged into production.
Risk Four: Supply-Chain Cyber Risk Extends Beyond Direct Technology Providers
Manufacturing supply chains create two distinct forms of cyber dependency.
The first comes from technology suppliers: software companies, managed service providers, cloud platforms, equipment vendors and organisations with privileged access to systems.
The second comes from the industrial supply chain itself.
A manufacturer may depend on specialist suppliers for components, materials, logistics or engineering services. If one of those organisations suffers significant disruption, the effect can propagate to customers even when their own systems remain secure.
The significance of a supplier therefore depends on the operational dependency it creates, not simply its size.
National evidence suggests that formal supplier cyber review remains relatively uncommon. The 2025/26 Cyber Security Breaches Survey found that 15% of businesses reviewed cyber risks associated with immediate suppliers, while only 6% considered the wider supply chain. The proportion reviewing immediate suppliers varied substantially by organisational size, from 12% of microbusinesses and 22% of small businesses to 30% of medium-sized and 48% of large businesses.
Those figures are national and should not be treated as a direct measurement of West Midlands manufacturing. They nevertheless illustrate the capability gap that can exist within supply chains containing organisations of very different sizes.
Manufacturers do not need to conduct detailed cyber audits of every supplier.
A more proportionate approach begins by identifying critical dependencies. Which supplier could stop production if unavailable? Which provider holds sensitive engineering information? Which organisation has privileged access to systems? Where would substitution be difficult or slow?
Those questions allow assurance effort to be concentrated where disruption would have the greatest consequence.
The same issue applies in reverse. West Midlands manufacturers supplying major automotive, aerospace, defence, infrastructure or other customers may increasingly be asked to demonstrate their own cyber controls.
Security capability can therefore influence both resilience and commercial participation.
Risk Five: An Incident Plan That Ignores Production Is Incomplete
Preventive security controls reduce risk but cannot guarantee that disruption will never occur.
Manufacturers therefore need to consider what happens when systems become unavailable or untrusted.
The 2025/26 Cyber Security Breaches Survey found that only 25% of UK businesses had a formal incident-response plan. The figure is useful as a national indication of preparedness, although it does not provide a specific measure for West Midlands manufacturers.
For an industrial business, effective preparation needs to extend beyond the conventional IT incident process.
If a production-management system becomes unavailable, can manufacturing continue safely? If remote access must be disabled during an investigation, which maintenance activities are affected? If identity systems are unavailable, can essential personnel still access the systems they need? If production data has to be restored, how will its integrity be verified before operations resume?
The answers depend on the organisation, which is why exercising is valuable.
A tabletop exercise can bring together IT, engineering, operations, senior management and communications staff around a realistic scenario. The purpose is not to predict an incident precisely, but to identify assumptions and dependencies before decisions have to be made under pressure.
Manufacturing businesses should also distinguish between backups and recovery.
Possessing a backup does not establish how long restoration will take, whether the backup includes all required configurations or whether production can operate while recovery is under way. Recovery priorities should reflect operational consequences rather than simply the technical order in which systems happen to be restored.
Where production has safety implications, incident planning also needs to respect established safety processes. Cyber response should not create additional physical risk through poorly coordinated changes to industrial systems.
Asset Visibility Connects All Five Risks
These five areas appear different, but they share a common dependency: organisations cannot manage industrial cyber risk effectively without understanding the systems on which operations rely.
An accurate asset inventory provides a starting point, but useful visibility extends further.
Manufacturers need to understand relationships between assets. A production machine may depend on a particular workstation for configuration, an identity service for authentication, a network connection for data exchange and an external supplier for maintenance. Protecting the machine while overlooking those dependencies gives an incomplete picture of operational risk.
This is where cyber risk assessment becomes more useful when conducted with engineering and operational staff rather than exclusively within IT.
Engineering teams understand production processes and equipment dependencies. IT teams understand enterprise systems and networks. Business leaders understand customer commitments and financial consequences. Cyber specialists can help connect those perspectives to threat and control decisions.
The result should be a prioritised understanding of the environment rather than an exhaustive technical catalogue that nobody uses.
For smaller manufacturers, that can begin with a relatively straightforward exercise: identify the systems without which the business could not operate normally, establish what those systems depend on and determine who can access them.
That information provides a much stronger basis for deciding where security investment should go.
Cyber Essentials Can Strengthen the Corporate Baseline
Many industrial cyber risks require controls specific to manufacturing environments, but weaknesses in ordinary corporate IT remain relevant because those systems can provide an initial route into the organisation.
Cyber Essentials offers a recognised baseline covering common technical controls. Certification has been increasing: the 2025/26 Breaches Survey found that 5% of businesses held Cyber Essentials, compared with 3% in the previous year, while adoption among small businesses increased from 5% to 12%.
For manufacturers, Cyber Essentials can help establish stronger foundations around conventional IT and may also support customer or procurement requirements.
It should not, however, be interpreted as certification of an entire industrial environment.
Operational technology can require additional assessment because the systems, protocols, equipment lifecycles and consequences differ from standard office computing. A business can therefore use Cyber Essentials as one component of its security approach while separately addressing risks associated with production technology.
The distinction helps avoid two opposite mistakes: dismissing baseline controls because industrial security is more complicated, or assuming that a corporate baseline resolves every OT risk.
Start with Operational Consequence Rather Than Cyber Complexity
Manufacturers can encounter an intimidating range of cyber terminology, frameworks, products and technical recommendations. Attempting to address everything simultaneously is rarely practical, particularly for smaller organisations without dedicated security teams.
Prioritisation becomes easier when the starting point is operational consequence.
A manufacturer can identify the production processes that are most important to delivery, the technology supporting those processes and the external organisations on which they depend. It can then consider realistic forms of disruption and establish which weaknesses deserve attention first.
This approach also helps distinguish different levels of support.
Some businesses may need straightforward improvements to identity, backups, network configuration or supplier access. Others operating complex industrial systems may require specialist OT security assessment. Organisations serving demanding customers may need help with assurance, certification or contractual requirements.
Regional support can make these routes easier to navigate. The West Midlands Cyber Hub can connect businesses with practical cyber support, specialist organisations, programmes and regional expertise without requiring manufacturers to understand the entire cyber support landscape before asking for help.
The objective should be proportionate improvement based on the business’s actual operating environment.
Industrial Cyber Resilience Is a Business-Continuity Discipline
The growth of connected manufacturing does not make digital technology undesirable. Connectivity, automation, remote support and data-driven production can improve productivity and competitiveness substantially.
They also change the dependencies that manufacturers need to manage.
The most useful way to approach industrial cyber security is therefore through the same disciplined thinking applied to other forms of operational resilience: understand critical assets and dependencies, reduce avoidable exposure, control access, prepare for disruption and test whether recovery arrangements work.
For West Midlands manufacturers, this approach has particular relevance because industrial capability remains central to the regional economy while digital technology is becoming more deeply embedded within production and supply chains.
Cyber resilience should consequently develop alongside that transformation.
A manufacturer does not need to solve every conceivable cyber problem before adopting new technology. It does need enough understanding of its operational dependencies to know where failure or compromise would create unacceptable consequences, and enough capability to manage those risks proportionately.
That is the practical foundation on which more sophisticated industrial cyber security can be built.